216.73.217.22

Analysis of Interlock Ransomware Attack on Healthcare Facilities

· Published 28/01/2025 18:12 · Modified 29/01/2025 17:02

Export JSON

Essential information

Published
28/01/2025 18:12
Modified
29/01/2025 17:02
Tags
2025-01-28 credential-theft data exfiltration double-extortion drive-by compromise healthcare interlock lateral movement ransomware
Related entities
1 intrusion sets (apt), 5 techniques (mitre), 1 malware, 2 others

Description

The group has been actively targeting facilities in the United States, causing significant disruptions and exposing sensitive patient data. The attacks involve techniques, using fake software updaters to deploy malware. The group employs tactics and has breached multiple organizations. ANY.RUN's Interactive Sandbox and Threat Intelligence Lookup tools can help organizations detect, investigate, and analyze these attacks at various stages, including initial compromise, execution, credential access, , and . The tools provide early detection of malicious domains, analysis of website content, expanded threat information, and discovery of additional indicators of compromise.

External references